How to Secretly Collect Digital Evidence from Computers
This patent describes a system for secretly collecting digital evidence and monitoring activity from computers using a single software agent that runs only in memory and sends data to a cloud server for smart analysis.
Patent Number
US 12739263
Status
Active
Filing Date
August 28, 2024
Grant Date
September 15, 2026
Expiration
~August 2044 (estimated)
Claims
0
Assignee
—
Inventors
—
Citations
0 forward · 0 backward
What it covers
The patent describes a system for monitoring computers and collecting digital evidence, called "forensic artifacts." It uses a single software program, or "agent," installed on the target computer, known as an "endpoint." This agent is designed to run entirely "in memory," meaning it avoids writing data to the computer's hard drive, making it harder to detect. The collected evidence is then broken into smaller pieces, or "chunked," prior to being sent to a "cloud server." This cloud server then organizes the data by "category," processes it, and can even summarize it or highlight the most important parts. The cloud server also allows users to ask questions about the data using everyday language, like asking a search engine. For example, a company's security team could use this system to investigate a computer suspected of being hacked, collecting evidence without leaving traces on the disk that an attacker might find and remove.
What it doesn't cover
- —Does not cover systems where separate software agents are used for monitoring and for collecting forensic evidence.
- —Does not cover agents that primarily store collected forensic data on the local computer's hard drive before transfer.
- —Does not cover transferring forensic artifacts to a cloud server without first breaking them into smaller chunks.
- —Does not cover cloud analysis systems that only provide raw data without summaries or identification of relevant information.
- —Does not cover systems that require complex, non-natural language commands to query monitoring data and forensic artifacts.
The clever bit
The truly clever part is the "in memory" operation of the agent, which allows it to collect sensitive "forensic artifacts" and monitoring data without leaving persistent traces on the target computer's disk. This stealthy approach significantly reduces the risk of detection and evidence tampering during an investigation.
Why it matters
This technology matters because it allows for more discreet and efficient cybersecurity investigations. By operating "in memory" and avoiding disk writes, the system makes it harder for sophisticated attackers to detect and tamper with the evidence collection process. The integrated agent and cloud-based analysis, including natural language queries, streamline the process of understanding complex security incidents, helping organizations respond faster to threats.
Real-world examples
- 1.Endpoint Detection and Response (EDR) platforms
- 2.Incident response tools
- 3.Cloud-based security analytics services
- 4.Digital forensics software
Generated by PatentBrief · Not legal advice · patentbrief.org
US 12739263 · 2026